CVE-2024-41975: Codesys Edge Gateway

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.

Affected products

  • Codesys Codesys Edge Gateway: before 3.5.21.0 (fixed in 3.5.21.0)
  • Codesys Codesys Gateway For Windows: before 3.5.21.0 (fixed in 3.5.21.0)

Published 2025-03-18. Last modified 2026-06-17.